Floating Network Identity Management via Distributed Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Dynamic networking environments, such as cloud networks with multiple user devices, pose challenges for configuration and network management due to their ephemeral nature and the difficulty in maintaining unambiguous identities for computing resources as they join or leave the network automatically.
Innovation Solution
The implementation of a floating network system using distributed agents on hosts across multiple networks, where each node is generated with unique credentials based on a trust relationship path from the root node, enabling dynamic identity management and communication policies across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud instances are automatically provisioned and decommissioned to accommodate operational load, then the scalability and adaptability of the network is improved, but the difficulty of maintaining unambiguous identities for computing resources increases
Solution Approach 1:
The patent applies preliminary action by pre-provisioning identity credentials (such as certificates or tokens) in the image or configuration template of cloud instances before they are deployed. When cloud instances are automatically provisioned, they inherit these pre-configured identity credentials, enabling them to join the network immediately with unambiguous identities without requiring post-provisioning identity configuration. This resolves the contradiction by enabling scalability through automatic provisioning while maintaining simple identity management through pre-configuration.
2Adaptability or versatility
If multiple user devices are allowed to join the network dynamically, then the versatility and user freedom of the network is improved, but the complexity of network configuration and management increases
Solution Approach 1:
The patent applies universality by implementing a standardized identity credential system that works across all types of user devices (cloud instances, personal computers, mobile devices). Instead of requiring device-specific configuration procedures, the system uses a universal credential format and authentication mechanism that any device can adopt. This resolves the contradiction by enabling diverse user devices to join the network freely while keeping configuration management simple through standardization.
3Productivity
If cloud instances are rapidly provisioned and decommissioned, then the responsiveness and automation level of the network is improved, but the reliability of maintaining consistent identity information decreases
Solution Approach 1:
The patent applies copying by creating identity credentials as immutable templates or images that are replicated to each cloud instance during provisioning. Instead of generating unique identity information dynamically for each instance (which could lead to inconsistencies), the system copies verified, pre-approved identity templates. This ensures that every cloud instance, regardless of when it is provisioned or decommissioned, maintains consistent and reliable identity information that adheres to network policies, while still enabling rapid automated provisioning.
Data Source
AI summary
Embodiments are directed to towards cloud scale automatic identity management. A floating network may be established using agents operative on hosts across one or more networks. Each node of the floating network is resident on host (computer or cloud instance) that includes an agent configured to perform one or more networking tasks that establish the floating network. Parent nodes may be nodes designated as points in the floating network for adding additional nodes. Accordingly, each parent node includes at least one parent agent that includes at least parent credentials. Agent installers provided to a host may generate a child agent for the host that includes child credentials generated based on its parent credentials. An unambiguous identity value for the new child node may be determined by tracing a trust relationship path from the child node to the root node of the floating network.


